OPSWAT MD Kiosk (MetaDefender Kiosk) is a secure removable media inspection solution designed to prevent malware and unauthorized files from entering sensitive environments through USB drives and other portable media. By combining controlled access, multiscanning, Deep Content Disarm and Reconstruction (CDR), and customizable security policies, MetaDefender Kiosk helps organizations create a trusted checkpoint before files are transferred into critical networks.
Quick Benefits
- Secure inspection of USB and removable media
- Protection against file-borne malware threats
- Multi-engine malware scanning
- Deep Content Disarm and Reconstruction
- Support for isolated and air-gapped environments
- Prevention of unauthorized file transfers
- Secure media validation before network access
- Integration with MetaDefender Core capabilities
- Customizable security policies and workflows

OPSWAT MD Kiosk At a Glance
What it is: Secure removable media inspection platform
Product name: MetaDefender Kiosk
Parent category: OPSWAT License
Primary role: Inspect and sanitize removable media before allowing files into protected environments
Main protection area: USB drives, external storage devices, and portable media
Core technology: MetaDefender Core integration and multiscanning
Additional security technologies: Deep CDR, malware scanning engines, file validation, and policy enforcement
Deployment models: Standalone kiosk, virtual deployment, and controlled access stations
Typical environments: Government, defense, critical infrastructure, manufacturing, healthcare, financial services, and isolated networks
Management: Local Kiosk interface and MetaDefender management components
License Overview
An OPSWAT MD Kiosk License provides the authorization to deploy MetaDefender Kiosk for secure removable-media inspection workflows.
Unlike traditional endpoint security products that focus on continuously running protection agents, MetaDefender Kiosk is designed as a controlled inspection point. The organization defines where portable media enters the environment, and the kiosk verifies the content before allowing files to continue into trusted systems.
The licensing structure is usually based on the deployed kiosk instance and the security capabilities required for that environment. Since MetaDefender Kiosk relies on MetaDefender Core technologies, the final configuration may include additional requirements for scanning engines, Deep CDR, and other security modules.
Organizations operating high-security environments often combine Kiosk with offline activation and controlled update processes because the inspection station may exist inside isolated or restricted networks.
Product Overview
Secure Removable Media Inspection
Portable storage devices remain a common method for transferring files between disconnected environments.
USB drives, external hard disks, and other removable devices can introduce:
- Malware
- Ransomware
- Malicious documents
- Hidden executable files
- Unauthorized data
- Vulnerable software components
MetaDefender Kiosk creates a controlled checkpoint where media can be inspected before entering the protected network.
The user connects the device to the kiosk, files are analyzed according to configured security policies, and only approved content can continue through the workflow.
Multi-Engine Malware Scanning
One of the core capabilities of MetaDefender Kiosk is integration with MetaDefender Core multiscanning.
Instead of relying on a single antivirus engine, files can be analyzed using multiple security engines with different detection technologies.
This approach improves detection coverage against:
- Known malware
- Suspicious executables
- Malicious documents
- Archived threats
- File-based attacks
The number of scanning engines available depends on the selected MetaDefender licensing configuration.
Deep Content Disarm and Reconstruction
Many attacks use legitimate document formats to deliver malicious content. Deep CDR provides an additional security layer by rebuilding supported files and removing potentially dangerous elements while preserving the usable information.
For example, documents containing embedded objects, scripts, or active components can be sanitized before being transferred into a protected environment. This capability is particularly important for organizations that must accept external documents but cannot risk introducing unknown content.
Options and Licensing Models
| Licensing Option | Description | Suitable For |
|---|---|---|
| Standalone Kiosk Deployment | License for a dedicated removable-media inspection station | Organizations requiring physical inspection points |
| MetaDefender Core Integration | Uses Core security technologies for scanning and advanced analysis | Environments requiring multi-layer file protection |
| Multi-Engine Scanning Package | Enables multiple malware detection engines | High-security environments requiring broader detection |
| Deep CDR Module | Sanitizes supported documents before release | Organizations protecting against unknown document threats |
| Adaptive Sandbox Integration | Adds behavioral analysis for suspicious files | Advanced malware investigation workflows |
| Offline Deployment License | Supports isolated environments without direct internet connectivity | Air-gapped and restricted networks |
| Multi-Kiosk Deployment | Supports multiple inspection stations across locations | Large organizations and distributed facilities |
| Enterprise Security Configuration | Combines multiple security modules and policies | Critical infrastructure and regulated environments |
Features and Benefits
The main value of OPSWAT MD Kiosk is controlling one of the most difficult security challenges: transferring files into trusted environments.
Many organizations cannot completely prohibit USB devices because operational requirements require external data exchange. Instead of allowing unrestricted access, Kiosk creates a controlled security gateway.
The combination of multiscanning and Deep CDR provides two different protection approaches. Malware engines identify known threats, while CDR reduces the risk from unknown malicious content hidden inside supported files.
This makes MetaDefender Kiosk particularly suitable for environments where traditional endpoint security alone is insufficient.
Another important advantage is operational flexibility. The same security concept can be deployed in a small number of inspection stations or expanded across multiple facilities.
Compatibility and Requirements
Before purchasing an OPSWAT MD Kiosk License, evaluate:
- Number of kiosk stations required
- Supported operating system
- USB and removable-media requirements
- Average media inspection volume
- Maximum file sizes
- Required scanning engines
- Deep CDR requirements
- Sandbox requirements
- Offline operation requirements
- Network isolation level
- Update process
- Audit and reporting requirements
- Integration with existing MetaDefender components
Hardware sizing is also important because large files, multiple scanning engines, and advanced analysis modules increase processing requirements.
Activation and Deployment
A typical MetaDefender Kiosk deployment includes:
- Install the Kiosk application on the designated system
- Configure removable-media policies
- Activate the OPSWAT license
- Connect MetaDefender Core where required
- Configure scanning engines and modules
- Define approval and blocking rules
- Test inspection workflows
- Deploy into production
For isolated environments, administrators can use offline activation methods and controlled update procedures. A common deployment process in restricted networks includes transferring license files, malware engine updates, and configuration packages through approved secure channels.
Pricing and Quote Process
Pricing for OPSWAT MD Kiosk depends on deployment size, security capabilities, and required integrations.
Before requesting a quote, prepare:
- Number of kiosk installations
- Deployment locations
- Required operating environment
- Number of inspection stations
- Required scanning engines
- Deep CDR requirements
- Sandbox requirements
- Offline deployment requirements
- Expected media volume
- File-size requirements
- Reporting requirements
- Support requirements
OPSWAT pricing depends on your product family, MetaDefender modules, deployment model, file security requirements, license term, and support needs.
